CVE-2014-5212: XSS
Published Dec 19, 2014
·Updated
Cross-site scripting (XSS) vulnerability in nds/search/data in iMonitor in Novell eDirectory before 8.8 SP8 Patch 4 allows remote attackers to inject arbitrary web script or HTML via the rdn parameter.
Affected Software
1 affected component
Novell eDirectory<=8.8
Event History
Dec 19, 2014
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-5212?
CVE-2014-5212 is considered a medium severity cross-site scripting (XSS) vulnerability.
2
How do I fix CVE-2014-5212?
To fix CVE-2014-5212, update to Novell eDirectory version 8.8 SP8 Patch 4 or later.
3
What does CVE-2014-5212 affect?
CVE-2014-5212 affects the iMonitor feature in Novell eDirectory versions before 8.8 SP8 Patch 4.
4
What is the impact of CVE-2014-5212?
The impact of CVE-2014-5212 allows remote attackers to inject arbitrary web script or HTML which may lead to data theft or session hijacking.
5
Is CVE-2014-5212 limited to specific browsers?
CVE-2014-5212 is not limited to specific browsers and affects any client that interacts with the vulnerable iMonitor interface.